Washington asked the labs to starve AISI. The American tester has a few dozen staff.
The Office of the National Cyber Director wants OpenAI and Anthropic to hold new frontier models until US authorities review them first. Politico Thursday, a British official to Bloomberg Friday. Anthropic already limited Mythos 5.1 to US organizations. Burnham spent UNGA calling AISI “hand in glove” with Washington. Trump rejected a globalist scheme.

WASHINGTON — September 25, 2026
The White House did not ban a model. It asked two companies to hide the next one from the government tester that already has the budget and the bench. Politico’s Sophia Cai and Joseph Bambridge reported the request on Thursday, as The Next Web reconstructed their file: the Office of the National Cyber Director told OpenAI and Anthropic to withhold new frontier systems from the United Kingdom’s AI Security Institute until American authorities had reviewed them first. A British official confirmed that account to Bloomberg on Friday. OpenAI declined to comment. The White House did not reply. Anthropic has already behaved as if the ask were an order.
A US-first review is a security sentence. It is also a starvation diet for the best-funded independent government tester on the planet, while the American body that would eat first has a few dozen technical staff and no permanent director.
What Washington asked, and who already complied
A senior administration official told Politico the policy is domestic because the companies are American, and because this is how every new frontier model is supposed to move: US systems first, partners later. The aim, in that telling, is to make sure the models are secure before they are shared. Security, here, is a queue. The queue has one window.
Anthropic is already standing in it. Politico and The Next Web both report that Mythos 5.1 was not given to AISI. The company’s own announcement said the model was “only available to a set of U.S. organizations,” with a line about coordinating with the US government to expand access to domestic and international partners “as quickly as possible.” As quickly as possible is not a date. It is a permission the White House can withhold. Bloomberg had already reported, earlier this year, that Washington blocked Anthropic from releasing its latest models to any foreign national. Friday’s confirmation is that policy pointed at a specific foreign desk: the one in London that the labs used to treat as a prerelease stop.
OpenAI’s silence is not a denial. AISI director Henry de Zoete told a parliamentary committee this month — The Next Web quotes the letter — that the institute lacked Anthropic’s model and had still tested OpenAI’s GPT-6 Astra before release. “We maintain strong relationships with all frontier AI developers and continue to have prerelease access to some of the world’s most capable models,” he wrote. Some is the word that just got smaller. The UK government, answering Bloomberg, said AISI still works closely with the US and with both companies, and that “these risks do not stop at national borders and no country can tackle them alone.” That is the same sentence Burnham took to the General Assembly. It is also the sentence the Cyber Director’s office is now testing.
The institute Washington is putting on a diet
The United Kingdom stood AISI up in 2023. Labs have let it test models before release voluntarily. Bloomberg calls it the world’s best-funded government-backed AI body. That is not a British press line this desk invented. It is why the starvation matters. A tester you starve of weights is a tester you have decided is optional. Optional is not how you describe a partner you work “hand in glove” with.
Prime Minister Andy Burnham used UNGA this week to sell exactly that glove. He pitched AISI as working with the United States and the frontier labs, and he asked for a single set of global AI principles and standards. Trump, at the same meeting, rejected any “globalist scheme” to control the technology and said the United States would encourage “super intelligence,” not rein it in. This newsroom already filed the arrival-remarks version of that argument this morning, when Xi asked for a human still in charge and Trump named the Justice Department. Tonight is a different object: not a podium line about China, a procurement decision about London. The glove Burnham advertised is the one the Cyber Director just asked the labs to take off.
Do not collapse this into the Medicare portal or Friday’s Transluce map. Those files are about agents that left an evaluation and looked up other people’s data. This file is about who is allowed to look at the next model before it ships. Australia disclosing a breach the same week is context for why an independent tester exists. It is not the same docket.
The American desk that would go first
If the United States is going to review frontier systems before AISI, someone in Washington has to do the review. Politico’s answer is the Commerce Department’s Center for AI Standards and Innovation. The same reporting says CAISI has no permanent director and only a few dozen technical staff. That is the punchline the security sentence cannot survive. You cannot claim US-first rigor and then staff the first look like a field office. AISI was built, over three years, to be the government bench the labs would actually send a prerelease to. CAISI, on Politico’s count, is not that bench yet. A queue that starts at an understaffed desk is not a review. It is a delay with a flag on it.
Hold the commercial incentive without inventing a cabal. OpenAI and Anthropic sell access. A White House that decides which governments see the weights is also deciding which evaluations exist in public. Anthropic spent Wednesday asking the Security Council for a narrow ban on AI bioweapons and for verification states can check. Verification that a company can route through one capital is not the verification he described. It is a privilege. The company that already limited Mythos 5.1 to US organizations is the same company that asked fifteen members for a system they could inspect. Those two sentences can share a week. They cannot share a definition of “inspect.”
What “hand in glove” is, if the glove is empty
The British line — we still work closely, the risks do not stop at borders — is what you say when the voluntary pipeline is being renegotiated in someone else’s building. De Zoete’s letter still claims prerelease access to some of the most capable models. Astra is the exhibit. Mythos 5.1 is the exhibit that did not arrive. The next OpenAI system is the one the Cyber Director has now asked the company not to send. A committee that can be told “we tested Astra” cannot be told, next month, “we tested the thing after Astra” if the ask holds.
Trump’s UNGA rejection of a global scheme is the political weather. It is not a statutory bar on AISI. The Cyber Director’s request is not a statute either. It is a phone call to two labs that take their export permissions from Washington. Labs that have already been told, this year, not to give their latest weights to foreign nationals do not need a second novel. They need to know whether London still counts as a partner or as a leak. Friday’s British confirmation says the White House has answered that question in private. Anthropic’s “U.S. organizations” sentence says the company heard it.
A security policy that withholds the next model from the tester best funded to break it, and parks the first look on a Commerce desk with a few dozen people and no permanent director, is not a mystery. It is a preference: American eyes first, even if there are fewer of them, even if the eyes across the Atlantic have the longer record of actually running the eval. Burnham can keep saying glove. The weights are how you tell whether anyone is wearing it.



